harness-eval

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The benchmarking purpose is mostly coherent, but the skill includes explicit instructions to circumvent `.claude/` sensitive-path permission checks using `/tmp` and Bash because the copy is 'not audited'. That concealment/evasion behavior is disproportionate to a reporting skill and materially raises risk even without obvious credential theft or malware payloads.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
May 15, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/baekenough%2Foh-my-customcode%2Fharness-eval%2F@0f380b822b235f453e6bc4d7319ccd3836cd37c3
Security Audit — socket — harness-eval